Post #3675908
2026-07-08 15:45 UTC
No matter how smart you think you are, an LLM is always stupider. It's a dangerous, powerful unpredictable tool that will out-dumb your harness.
"TL;DR: Noma Labs discovered a critical prompt injection vulnerability within GitHub’s new Agentic Workflows, allowing an unauthenticated attacker to silently pull data from private repositories by posting a crafted GitHub Issue in a public repository belonging to the same organization as the private repositories."
#aislop
https://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos/
Replies (0)
No replies.